Configuring A Mac Authentication Critical Vlan - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Feature
Port intrusion protection
802.1X guest VLAN on a
port that performs
MAC-based access control
If MAC authentication clients in your network cannot trigger an immediate DHCP-assigned IP address
renewal in response to a VLAN change, the MAC authentication users cannot access authorized network
resources immediately after a MAC authentication is complete. As a solution, remind the MAC
authentication users to release their IP addresses or repair their network connections for a DHCP
reassignment after MAC authentication is complete.
Before you configure a MAC authentication guest VLAN on a port, complete the following tasks:
Enable MAC authentication.
Enable MAC-based VLAN on the port.
Create the VLAN to be specified as the MAC authentication guest VLAN.
To configure a MAC authentication guest VLAN:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Specify a MAC
authentication guest
VLAN.

Configuring a MAC authentication critical VLAN

Follow the guidelines in
Table 9 Relationships of the MAC authentication critical VLAN with other security features
Feature
Quiet function of MAC
authentication
Super VLAN
Relationship description
The MAC authentication guest VLAN function
has higher priority than the block MAC action
but lower priority than the shut down port
action of the port intrusion protection feature.
The MAC authentication guest VLAN has a
lower priority.
Command
system-view
interface interface-type
interface-number
mac-authentication guest-vlan
guest-vlan-id
Table 9
when you configure a MAC authentication critical VLAN on a port.
Relationship description
The MAC authentication critical VLAN function has
higher priority.
When a user fails MAC authentication because no
RADIUS authentication server is reachable, the user
can access the resources in the critical VLAN, and
the user's MAC address is not marked as a silent
MAC address.
You cannot specify a VLAN as both a super VLAN
and a MAC authentication critical VLAN.
116
Reference
See
"Configuring port
security."
See
"Configuring
Remarks
N/A
N/A
By default, no MAC authentication guest
VLAN is configured.
You can configure only one MAC
authentication guest VLAN on a port.
Reference
See
"MAC authentication
timers."
See Layer 2
Switching Configuration
Guide.
802.1X."
LAN

Advertisement

Table of Contents
loading

Table of Contents